utxo the webmaster 🧑💻
· 5w
Btcpayserver exploit explained:
The old check only refused Basic auth if the user had FIDO2 credentials (a hardware security key). If you secured your account with TOTP (Google Authenticator etc.), ...
So if they have your username and password they have your corn, is that it?